Skip to main content
Glama
ry-ops

fortigate-mcp-server

by ry-ops

create_service_group

Create a service group to combine multiple services into a single firewall policy, reducing policy count and helping stay within evaluation license limits.

Instructions

Create a service group, e.g. K3S-MGMT = [SSH, K8S-API, PING]. Grouping services lets one policy cover what would otherwise need several, which helps under the evaluation license's 3-policy limit.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesGroup name
vdomNoVDOM (default: FORTIGATE_VDOM, usually root)
extraNoExtra FortiOS attributes merged into the request body as-is (hyphenated keys)
commentNoComment
membersYesService or group names

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

A3.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden. It adds genuinely useful context (the evaluation license's 3-policy limit motivating group creation) but omits operational traits: required permissions, whether members must already exist, failure behavior, or idempotency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the verb and resource, then a compact example and a one-line rationale. No filler, though the license-limit sentence is context rather than strictly necessary to invoke the tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 5-param create tool with no annotations and no output schema, the description covers purpose and the members example but leaves the 'extra' passthrough object, vdom defaulting, and mutation outcomes unexplained. Adequate but with clear gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, and the example adds meaning beyond the schema by illustrating the shape of both required params (name = group label, members = list of service/group names). It does not explain the vdom or extra parameters, but the example lifts it above baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (create a service group) and reinforces it with a concrete example (K3S-MGMT = [SSH, K8S-API, PING]). It is distinguishable from create_service (a single service) and create_address_group, though it never names a sibling explicitly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives a rationale for when to use grouping (covering several services with one policy under the 3-policy license limit), which implies usage. However it never states when NOT to use it or points to alternatives like create_service or update_service_group, leaving the agent to infer the routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.